National Cyber-Alert System
Vulnerability Summary for CVE-2005-1982
Original release date:08/10/2005
Last revised:09/10/2008
Source:
US-CERT/NIST
Overview
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
Impact
CVSS Severity (version 2.0):
Impact Subscore:
4.9
Exploitability Subscore:
3.9
CVSS Version 2 Metrics:
Access Vector: Locally exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type:Allows unauthorized disclosure of information; Allows unauthorized modification
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
US-CERT Vulnerability Note: VU#477341
Name: VU#477341
External Source: MS
Name: MS05-042
Type: Patch Information
External Source: SECUNIA
Name: 16368
Type: Advisory; Patch Information
External Source: BID
Name: 14520
External Source: SECTRACK
Name: 1014642
US Government Resource: oval:org.mitre.oval:def:100106
Name: oval:org.mitre.oval:def:100106
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:100104
Name: oval:org.mitre.oval:def:100104
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:100102
Name: oval:org.mitre.oval:def:100102
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:100100
Name: oval:org.mitre.oval:def:100100
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:100098
Name: oval:org.mitre.oval:def:100098
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:100096
Name: oval:org.mitre.oval:def:100096
Type: Tool Signature